2026

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI 2026-09-28 at 14:58 By AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users. According to Okta’s […]

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI Read More »

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent 2026-09-28 at 14:46 By Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that’s targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. “The implant installs the framework unchanged, then overwrites its SOUL.md persona […]

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent Read More »

DC Health Agency Exposes 400,000 Beneficiary Records

DC Health Agency Exposes 400,000 Beneficiary Records 2026-09-28 at 14:29 By Ionut Arghire The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed. The post DC Health Agency Exposes 400,000 Beneficiary Records appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

DC Health Agency Exposes 400,000 Beneficiary Records Read More »

Hong Kong regulators expand financial reporting oversight to licensed crypto firms

Hong Kong regulators expand financial reporting oversight to licensed crypto firms 2026-09-28 at 14:09 By Cointelegraph by Ezra Reguerra The SFC and AFRC signed a new MoU extending financial reporting, audit and compliance cooperation to licensed virtual asset service providers. This article is an excerpt from Cointelegraph.com News View Original Source

Hong Kong regulators expand financial reporting oversight to licensed crypto firms Read More »

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign 2026-09-28 at 13:56 By Ionut Arghire The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273. The post Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign Read More »

Email spam filters cost GOP fundraisers estimated $117M in donations last year: bombshell study

Email spam filters cost GOP fundraisers estimated $117M in donations last year: bombshell study 2026-09-28 at 13:45 By Thomas Barrabi The little-noticed analysis, published on July 7 by Cameron Ellis of the University of Iowa and Lars Powell of the University of Alabama, could reignite long-running complaints by Republicans who have accused Google and other […]

Email spam filters cost GOP fundraisers estimated $117M in donations last year: bombshell study Read More »

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources 2026-09-28 at 13:44 By The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor’s tradecraft. […]

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources Read More »

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally 2026-09-28 at 13:44 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below – CVE-2026-88771 (CVSS score: […]

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally Read More »

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections 2026-09-28 at 13:40 By Associated Press A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform. The post New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections appeared first on SecurityWeek. This article […]

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections Read More »

Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog

Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog 2026-09-28 at 13:27 By Eduard Kovacs The platform combines open source software and a reference system design to keep AI agents within set boundaries. The post Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog Read More »

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) 2026-09-28 at 12:51 By Zeljka Zorz Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices. Rumors about their existence and active exploitation popped […]

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) Read More »

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability 2026-09-28 at 12:44 By Ionut Arghire The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised. The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability Read More »

Bitcoin drops under $83K as liquidity hunting keeps bulls from targeting yearly open

Bitcoin drops under $83K as liquidity hunting keeps bulls from targeting yearly open 2026-09-28 at 12:03 By Cointelegraph by William Suberg Bitcoin joined US stock futures in dropping on Monday after US president Donald Trump did not commit to permanently halting strikes on Iran. This article is an excerpt from Cointelegraph.com News View Original Source

Bitcoin drops under $83K as liquidity hunting keeps bulls from targeting yearly open Read More »

Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts

Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts 2026-09-28 at 11:45 By Sinisa Markovic A former U.S. Army soldier who was part of a group that stole data from telecom companies, including AT&T, has been sentenced to 70 months in prison. Cameron John Wagenius, 22, was part of the group that […]

Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts Read More »

LinkedIn tests a way for connections to verify your work history

LinkedIn tests a way for connections to verify your work history 2026-09-28 at 11:20 By Anamarija Pogorelec LinkedIn is testing a way for members to verify the work and education history of people they know. The platform prompts verified members to confirm that they worked or studied with a connection. Once that person receives enough […]

LinkedIn tests a way for connections to verify your work history Read More »

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug 2026-09-28 at 10:29 By Eduard Kovacs Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The post Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug Read More »

Scroll to Top